Overview
overview
10Static
static
10Redline_20_2.zip
windows7-x64
1Redline_20_2.zip
windows10-2004-x64
1Redline_20...er.exe
windows7-x64
1Redline_20...er.exe
windows10-2004-x64
1Redline_20...config
windows7-x64
3Redline_20...config
windows10-2004-x64
3Redline_20...er.pdb
windows7-x64
3Redline_20...er.pdb
windows10-2004-x64
3Redline_20...db.dll
windows7-x64
1Redline_20...db.dll
windows10-2004-x64
1Redline_20...db.pdb
windows7-x64
3Redline_20...db.pdb
windows10-2004-x64
3Redline_20...db.dll
windows7-x64
1Redline_20...db.dll
windows10-2004-x64
1Redline_20...db.pdb
windows7-x64
3Redline_20...db.pdb
windows10-2004-x64
3Redline_20...ks.dll
windows7-x64
1Redline_20...ks.dll
windows10-2004-x64
1Redline_20...ks.pdb
windows7-x64
3Redline_20...ks.pdb
windows10-2004-x64
3Redline_20...il.dll
windows7-x64
1Redline_20...il.dll
windows10-2004-x64
1Redline_20...il.pdb
windows7-x64
3Redline_20...il.pdb
windows10-2004-x64
3Redline_20...ub.exe
windows7-x64
10Redline_20...ub.exe
windows10-2004-x64
10Redline_20...st.exe
windows7-x64
1Redline_20...st.exe
windows10-2004-x64
1Redline_20...config
windows7-x64
3Redline_20...config
windows10-2004-x64
3Redline_20...CF.dll
windows7-x64
1Redline_20...CF.dll
windows10-2004-x64
1Analysis
-
max time kernel
117s -
max time network
126s -
platform
windows7_x64 -
resource
win7-20240419-en -
resource tags
arch:x64arch:x86image:win7-20240419-enlocale:en-usos:windows7-x64system -
submitted
02-07-2024 08:26
Behavioral task
behavioral1
Sample
Redline_20_2.zip
Resource
win7-20240220-en
Behavioral task
behavioral2
Sample
Redline_20_2.zip
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.exe
Resource
win7-20240508-en
Behavioral task
behavioral4
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.exe.config
Resource
win7-20240419-en
Behavioral task
behavioral6
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.exe.config
Resource
win10v2004-20240226-en
Behavioral task
behavioral7
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.pdb
Resource
win7-20240221-en
Behavioral task
behavioral8
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.pdb
Resource
win10v2004-20240611-en
Behavioral task
behavioral9
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Mdb.dll
Resource
win7-20240508-en
Behavioral task
behavioral10
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Mdb.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Mdb.pdb
Resource
win7-20240611-en
Behavioral task
behavioral12
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Mdb.pdb
Resource
win10v2004-20240508-en
Behavioral task
behavioral13
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Pdb.dll
Resource
win7-20240611-en
Behavioral task
behavioral14
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Pdb.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral15
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Pdb.pdb
Resource
win7-20240611-en
Behavioral task
behavioral16
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Pdb.pdb
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Rocks.dll
Resource
win7-20231129-en
Behavioral task
behavioral18
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Rocks.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral19
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Rocks.pdb
Resource
win7-20240419-en
Behavioral task
behavioral20
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.Rocks.pdb
Resource
win10v2004-20240508-en
Behavioral task
behavioral21
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.dll
Resource
win7-20240508-en
Behavioral task
behavioral22
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral23
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.pdb
Resource
win7-20240220-en
Behavioral task
behavioral24
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Mono.Cecil.pdb
Resource
win10v2004-20240508-en
Behavioral task
behavioral25
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/stub.exe
Resource
win7-20240508-en
Behavioral task
behavioral26
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/stub.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral27
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.Host.exe
Resource
win7-20240611-en
Behavioral task
behavioral28
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.Host.exe
Resource
win10v2004-20240226-en
Behavioral task
behavioral29
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.Host.exe.config
Resource
win7-20231129-en
Behavioral task
behavioral30
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.Host.exe.config
Resource
win10v2004-20240508-en
Behavioral task
behavioral31
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.WCF.dll
Resource
win7-20240419-en
Behavioral task
behavioral32
Sample
Redline_20_2/Redline_20_2_stealer-main/Kurome.Host/Kurome.WCF.dll
Resource
win10v2004-20240611-en
General
-
Target
Redline_20_2/Redline_20_2_stealer-main/Kurome.Builder/Kurome.Builder.exe.config
-
Size
189B
-
MD5
5a7f52d69e6fca128023469ae760c6d5
-
SHA1
9d7f75734a533615042f510934402c035ac492f7
-
SHA256
498c7f8e872f9cef0cf04f7d290cf3804c82a007202c9b484128c94d03040fd0
-
SHA512
4dc8ae80ae9e61d2801441b6928a85dcf9d6d73656d064ffbc0ce9ee3ad531bfb140e9f802e39da2a83af6de606b115e5ccd3da35d9078b413b1d1846cbd1b4f
Malware Config
Signatures
-
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Modifies registry class 1 IoCs
Processes:
cmd.exedescription ioc process Key created \REGISTRY\USER\S-1-5-21-481678230-3773327859-3495911762-1000_Classes\Local Settings cmd.exe -
Suspicious behavior: CmdExeWriteProcessMemorySpam 1 IoCs
Processes:
AcroRd32.exepid process 2520 AcroRd32.exe -
Suspicious behavior: GetForegroundWindowSpam 1 IoCs
Processes:
AcroRd32.exepid process 2520 AcroRd32.exe -
Suspicious use of SetWindowsHookEx 2 IoCs
Processes:
AcroRd32.exepid process 2520 AcroRd32.exe 2520 AcroRd32.exe -
Suspicious use of WriteProcessMemory 4 IoCs
Processes:
cmd.exedescription pid process target process PID 1520 wrote to memory of 2520 1520 cmd.exe AcroRd32.exe PID 1520 wrote to memory of 2520 1520 cmd.exe AcroRd32.exe PID 1520 wrote to memory of 2520 1520 cmd.exe AcroRd32.exe PID 1520 wrote to memory of 2520 1520 cmd.exe AcroRd32.exe
Processes
-
C:\Windows\system32\cmd.execmd /c C:\Users\Admin\AppData\Local\Temp\Redline_20_2\Redline_20_2_stealer-main\Kurome.Builder\Kurome.Builder.exe.config1⤵
- Modifies registry class
- Suspicious use of WriteProcessMemory
-
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe"C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AcroRd32.exe" "C:\Users\Admin\AppData\Local\Temp\Redline_20_2\Redline_20_2_stealer-main\Kurome.Builder\Kurome.Builder.exe.config"2⤵
- Suspicious behavior: CmdExeWriteProcessMemorySpam
- Suspicious behavior: GetForegroundWindowSpam
- Suspicious use of SetWindowsHookEx
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEventsFilesize
3KB
MD5200620164acaec30722ada30db854940
SHA182848b5d92dc680f40c4f6e319fbf0872738f74d
SHA25679075d197858d9c0dc60de852608d47339cf63111280f78b16bbb7267e2057c2
SHA5128c6d543df3f068293ab727fa3414fad8b30e254d8090410d49eaf192bd585026659c52c5c39e33676be5472de99ab3163c12b434d8189a789034894ce8b170be